Team members and roles

Adding colleagues to your account, what admin, editor and viewer can each do, and how to remove someone's access.

Updated 8/20/2026

Everyone who needs to work in PocketPass should have their own login. Shared accounts make it impossible to tell who changed what, and awkward when someone leaves.

Manage this under Settings → Team.

Adding someone

    1. Open Settings → Team.
    2. Enter their email address.
    3. Choose a role.
    4. Add them.

If they already have a PocketPass login, they're added straight away and we email to let them know. If they don't, we send an invitation to that address - they set a password, and the access is waiting for them.

The roles

There are three.

Admin can do everything an editor can, plus the things that carry commercial or security weight: managing the team, billing, and your own Apple certificate.

Editor runs the programme day to day. Create and edit templates, issue and edit passes, send notifications, connect a CRM, manage API keys and webhooks. They can't change the team or touch billing.

Viewer can see everything but change nothing. They can browse passes, templates and notification reports, but can't issue, edit, send or configure.

Choosing a role

Give editor to whoever designs templates, issues passes and sends messages. It's the right default for most people, and it's what the invite form picks unless you change it.

Keep admin for the people who should also be able to add and remove colleagues, change the plan, or replace the Apple certificate.

Give viewer to people who need visibility without responsibility: someone on a support desk who needs to look up a customer's pass, a manager who wants to see how campaigns performed.

When in doubt, start someone as a viewer. It's a two-second change to promote them once they've found their feet, and it avoids a new person discovering the bulk-archive button before they know what it does.

A viewer can read everything in the account, including the API keys and webhooks pages - so they can see a webhook signing secret even though they can't change it. Treat viewer as "trusted, read-only", not as a role for someone outside your organisation.

Changing someone's role

Pick a new role from the dropdown on their row and save.

You can't demote the last admin. Every account needs at least one, otherwise nobody could ever change anything again - including the setting that got you into that state. Promote someone else first, then change your own role.

Removing someone

Choose Remove on their row and confirm. They lose access immediately.

The same last-admin protection applies - you can't remove the only admin.

Removing someone doesn't delete their PocketPass login, and it doesn't touch anything they created. Templates, passes and campaigns belong to the account, not to the person who made them.

Removing a teammate does not revoke API keys. Keys belong to the account and keep working. If the person who left had access to a key, revoke it separately under API keys and issue a replacement. See API keys and authentication.

When someone leaves

A short checklist:

  1. Remove them from the team.
  2. Revoke any API keys they had access to, and create replacements for whatever was using them.
  3. Check your webhook endpoints - if any point at a system only they could reach, update or remove them.

Where to go next

More in Account & settings